logo

Single Actor Bypassed Open VSX Security with “Disposable” Tools

ID: 0a45ca6a-6f65-5bd1-a004-42b48ff5e860

STIX ID: report--0a45ca6a-6f65-5bd1-a004-42b48ff5e860

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Ddos

...
...

Security researcher Yeeth Security detected a sophisticated campaign on the Open VSX marketplace (Apr 27–28, 2026) in which a single threat actor published 16 malicious extensions that appeared unrelated but used string-fragment reconstruction and regenerated bundles with disposable publisher identities to hide runtime payload URLs; analysis tied samples to a common payload host (github.com/francesca898/dqwffqw) and the malicious infrastructure remained active at time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.